Debian Linux vulnerabilities
9,953 known vulnerabilities affecting debian/debian_linux.
Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358
Vulnerabilities
Page 82 of 498
CVE-2017-3143P3MEDIUMCVSS 5.9v8.0v9.02019-01-16
CVE-2017-3143 [MEDIUM] CVE-2017-3143: An attacker who is able to send and receive messages to an authoritative DNS server and who has know
An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be able to manipulate BIND into accepting an unauthorized dynamic update. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S
nvd
CVE-2020-10232P3CRITICALCVSS 9.8v8.0v9.02020-03-09
CVE-2020-10232 [CRITICAL] CWE-787 CVE-2020-10232: In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability
In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaffsfs_istat() in fs/yaffs.c.
nvd
CVE-2019-16378P3CRITICALCVSS 9.8v9.0v10.02019-09-17
CVE-2019-16378 [CRITICAL] CWE-290 CVE-2019-16378: OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability w
OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect applications that consider a domain name to be relevant to the origin of an e-mail message.
nvd
CVE-2017-15399P3HIGHCVSS 8.8v8.0v9.0+1 more2018-08-28
CVE-2017-15399 [HIGH] CWE-416 CVE-2017-15399: A use after free in V8 in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to potential
A use after free in V8 in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2014-4914P3CRITICALCVSS 9.8v7.0v8.02017-12-29
CVE-2014-4914 [CRITICAL] CWE-89 CVE-2014-4914: The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parenthe
The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecified vectors.
nvd
CVE-2019-17542P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-10-14
CVE-2019-17542 [CRITICAL] CWE-787 CVE-2019-17542: FFmpeg before 4.2 has a heap-based buffer overflow in vqa_decode_chunk because of an out-of-array ac
FFmpeg before 4.2 has a heap-based buffer overflow in vqa_decode_chunk because of an out-of-array access in vqa_decode_init in libavcodec/vqavideo.c.
nvd
CVE-2020-7065P3HIGHCVSS 8.8v10.02020-04-01
CVE-2020-7065 [HIGH] CWE-121 CVE-2020-7065: In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with
In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and potentially code execution.
nvd
CVE-2021-43859P3HIGHCVSS 7.5v9.02022-02-01
CVE-2021-43859 [HIGH] CWE-400 CVE-2021-43859: XStream is an open source java library to serialize objects to XML and back again. Versions prior to
XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors an
nvd
CVE-2019-25032P3CRITICALCVSS 9.8v9.02021-04-27
CVE-2019-25032 [CRITICAL] CWE-190 CVE-2019-25032: Unbound before 1.9.5 allows an integer overflow in the regional allocator via regional_alloc. NOTE:
Unbound before 1.9.5 allows an integer overflow in the regional allocator via regional_alloc. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
nvd
CVE-2020-28984P3CRITICALCVSS 9.8v9.0v10.02020-11-23
CVE-2020-28984 [CRITICAL] CVE-2020-28984: prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the cou
prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, display_outils, imessage, and spip_ecran parameters.
nvd
CVE-2013-2166P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-12-10
CVE-2013-2166 [CRITICAL] CWE-326 CVE-2013-2166: python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
nvd
CVE-2020-15866P3CRITICALCVSS 9.8v9.02020-07-21
CVE-2020-15866 [CRITICAL] CWE-787 CVE-2020-15866: mruby through 2.1.2-rc has a heap-based buffer overflow in the mrb_yield_with_class function in vm.c
mruby through 2.1.2-rc has a heap-based buffer overflow in the mrb_yield_with_class function in vm.c because of incorrect VM stack handling. It can be triggered via the stack_copy function.
nvd
CVE-2019-25038P3CRITICALCVSS 9.8v9.02021-04-27
CVE-2019-25038 [CRITICAL] CWE-190 CVE-2019-25038: Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE:
Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
nvd
CVE-2019-25039P3CRITICALCVSS 9.8v9.02021-04-27
CVE-2019-25039 [CRITICAL] CWE-190 CVE-2019-25039: Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The
Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
nvd
CVE-2018-1318P3HIGHCVSS 7.5v9.02018-08-29
CVE-2018-1318 [HIGH] CWE-20 CVE-2018-1318: Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted requ
Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted request. This affects versions Apache Traffic Server (ATS) 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versions.
nvd
CVE-2013-2167P3CRITICALCVSS 9.8v8.0v9.0+1 more2019-12-10
CVE-2013-2167 [CRITICAL] CWE-345 CVE-2013-2167: python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass
nvd
CVE-2020-7677P3CRITICALCVSS 9.8v10.02022-07-25
CVE-2020-7677 [CRITICAL] CVE-2020-7677: This affects the package thenify before 3.3.1. The name argument provided to the package can be cont
This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.
nvd
CVE-2007-1216P3CRITICALCVSS 9.0v3.1v4.02007-04-06
CVE-2007-1216 [CRITICAL] CWE-415 CVE-2007-1216: Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), as used by the Kerber
Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), as used by the Kerberos administration daemon (kadmind) in MIT krb5 before 1.6.1, when used with the authentication method provided by the RPCSEC_GSS RPC library, allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via a messag
nvd
CVE-2018-12387P3CRITICALCVSS 9.1v9.02018-10-18
CVE-2018-12387 [CRITICAL] CWE-20 CVE-2018-12387: A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple argumen
A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by 8 bytes after a bailout. This leaks a memory address to the calling function which can be used as part of an exploit inside the sandboxed content process. This vulnerability affects Firefox ESR < 60.2
nvd
CVE-2018-14633P3HIGHCVSS 7.0v8.0v9.02018-09-25
CVE-2018-14633 [HIGH] CWE-121 CVE-2018-14633: A security flaw was found in the chap_server_compute_md5() function in the ISCSI target code in the
A security flaw was found in the chap_server_compute_md5() function in the ISCSI target code in the Linux kernel in a way an authentication request from an ISCSI initiator is processed. An unauthenticated remote attacker can cause a stack buffer overflow and smash up to 17 bytes of the stack. The attack requires the iSCSI target to be enabled on the vi
nvd